CVE-2021-41411: XEE
Published Jun 16, 2022
·Updated
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
Affected Software
2 affected componentsFixes available
maven/org.drools:drools-core<=7.59.0.Final
7.60.0.Final
redhat Drools<7.6.0
Remediation
Patch Available
Event History
Jun 16, 2022
CVE Published
via MITRE·09:52 AM
Data Sourced
via MITRE·09:52 AM
Description
Jun 17, 2022
Advisory Published
via GitHub·12:01 AM
Frequently Asked Questions
1
What is CVE-2021-41411?
CVE-2021-41411 is an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java in drools <=7.59.x.
2
How severe is CVE-2021-41411?
CVE-2021-41411 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2021-41411?
The affected software versions are drools <=7.59.x.
4
How can I fix CVE-2021-41411?
To fix CVE-2021-41411, update drools to a version higher than 7.59.x.
5
Where can I find more information about CVE-2021-41411?
More information about CVE-2021-41411 can be found at the following link: [https://github.com/kiegroup/drools/pull/3808](https://github.com/kiegroup/drools/pull/3808)